System and method for acoustic two factor authentication
Abstract
Apparatus and method are disclosed for digital authentication and verification. In one embodiment, authentication involves storing a cryptographic key and a look up table (LUT), generating an access code using the cryptographic key; generating multiple parallel BPSK symbols based upon the access code; converting the BPSK symbols into multiple tones encoded with the access code using the LUT; and outputting the multiple tones encoded with the access code for authentication. In another embodiment, verification involves receiving multiple tones encoded with an access code; generating multiple parallel BPSK symbols from the multiple tones; converting the BPSK symbols into an encoded interleaved bit stream of the access code; de-interleaving the encoded interleaved bit stream; and recovering the access code from the encoded de-interleaved bit stream.

Term
Term ended
Expired 12 February 2023, 3.6 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
31 claims: 18 independent, 13 dependent
- 1THE CLAIMS DEFINING THE INVENTION ARE AS FOLLOWS:1. A method for authentication, including: providing at least a PIN and a confidential public key to an authorizing computer;5 establishing a communication link between the authorizing computer and at least one receiver remote from the computer, the communication link not being constrained to be secure;receiving, at the receiver, at least one acoustic signal representative of at least one private keygenerated signal, the receiver transforming the acoustic signal to a signature signal;receiving, at the receiver, the PIN, the PIN being received separately from the acoustic signal;0 encrypting the signature signal with the PIN to render an encrypted signature signal;and sending the encrypted signature signal to the authorizing computer for verification of the signature using the PIN and confidential public key.
- 2The method of Claim 1, wherein the act of encrypting is undertaken at the receiver.
- 6The method of Claim 3, wherein the token generates a signature signal by combining at least one message with the private key. 30
- 7The method of Claim 6, wherein the message includes at least a portion of at least one timestamp.
- 8The method of Claim 7, wherein the portion of the timestamp is a predetermined number of least significant bits of a timestamp having more bits than the predetermined number. 2003219752 01 May 2008
- 9A system for two-factor authentication over a link not constrained to be secure, including:at least one portable token generating at least one wireless signal representing a digitally signed message;at least one receiver receiving the wireless signal and a PIN, the PIN being received separately 5 from the wireless signal, the receiver encrypting the signed message with the PIN to render an encrypted signed message;and at least one authorizing computer receiving at least the encrypted signed message over the link, the authorizing computer accessing the PIN and a confidential public key to attempt to verify the signed message.
- 10The system of Claim 9, wherein the wireless signal also represents at least an ID of a confidential public key and a message that was signed by a private key corresponding to the public key to render the digitally signed message. 5
- 11The system of Claim 10, wherein the receiver sends the encrypted signed message, ID, and message that was signed to the authorizing computer.
- 12The system of Claim 10, wherein the authorizing computer decrypts the encrypted signed message using the PIN and then verifies the signed message by accessing the confidential public key 0 using the ID and using the confidential public key.
- 13A system for authentication including an authorizing computer accessing at least a PIN and a confidential public key and communicating over a link with at least one receiver remote from the computer, the communication link not being constrained to be secure, the system including:25 means for receiving, at the receiver, at least one wireless signal representative of at least one digital signature produced from a private key, the receiver transforming the wireless signal to a signature signal;means for receiving, at the receiver, the PIN;and means for encrypting the signature signal with the PIN to render an encrypted signature signal, 30 wherein the encrypted signature signal is sent to the authorizing computer over the link for verification of the signature using the PIN and confidential public key.
- 14The system of Claim 13, wherein the means for encrypting are at the receiver. 35
- 18The system of Claim 15, wherein the token generates a signature signal by combining at least one message with the private key.
- 19The system of Claim 18, wherein the message includes at least a portion of at least one timestamp.
- 23A computer readable medium containing instructions for controlling a computer system to perform a method, the method including:
- 2425 providing at least a PIN and a confidential public key to an authorizing computer;establishing a communication link between the authorizing computer and at least one receiver remote from the computer, the communication link not being constrained to be secure;receiving, at the receiver, at least one acoustic signal representative of at least one private keygenerated signal, the receiver transforming the acoustic signal to a signature signal;30 receiving, at the receiver, the PIN, the PIN being received separately from the acoustic signal;encrypting the signature signal with the PIN to render an encrypted signature signal;and sending the encrypted signature signal to the authorizing computer for verification of the signature using the PIN and confidential public key. 35 24. The computer readable medium Claim 23, wherein the act of encrypting is undertaken at the receiver. 2003219752 01 May 2008 25. The computer readable medium Claim 23 or 24, including transmitting the acoustic signal using a hand-held token.
- 2526. The computer readable medium any one of Claims 23 to 25, further including inputting a 5 desired transaction to the receiver, the authorizing computer authorizing the receiver to execute the transaction only if the signature is verified.
- 2627. The computer readable medium any one of Claims 23 to 26, wherein the signature is verified by:0 decrypting the encrypted signature signal using the PIN to render the signature signal;then verifying the signature signal using the confidential public key.
- 2728. The computer readable medium Claim 25, wherein the token generates a signature signal by combining at least one message with the private key.
- 2829. The computer readable medium Claim 28, wherein the message including at least a portion of at least one timestamp.
- 2930. The computer readable medium Claim 29, wherein the portion of the timestamp is a 0 predetermined number of least significant bits of a timestamp having more bits than the predetermined number.
- 3031. A method substantially in accordance with any one of the embodiments of the invention described herein and illustrated in the accompanying drawings.
- 3132. A system substantially in accordance with any one of the embodiments of the invention described herein and illustrated in the accompanying drawings. 1/1 WO 03/071770 PCT/US03/04387 FIG. 2
Independent claims31
46 paragraphs in 5 sections, as filed
The present invention relates generally to authentication using audio tones.
II. Background Of The Invention
As Internet use has grown, many types of convenient electronic commerce have been made possible, such as, for example, buying goods and services online, banking online, and using automatic teller machines (ATM) that are linked to remote banks. But the very convenience of electronic commerce has made it easier for thieves to steal valuable information and/or to pose as someone they are not to purchase goods, withdraw money from bank accounts, and so on.
Accordingly, affording security in electronic transactions is crucial. To this end, many electronic transactions are encrypted, to conceal private information being exchanged. But encryption is only one aspect of security, since it is possible for a thief to break the encryption or to come into possession of an otherwise valid item such as a credit card, pose as the owner, and participate in an encrypted transaction.
With this in mind, it readily may be appreciated that authentication is an important aspect of security. In terms of electronic commerce, the person seeking authentication does so through a computer interface. Consequently, it normally is pot feasible to resort to checking a biological feature of the person (appearance, handwritten signature, fingerprint, and so on) to verify that the person is who he says he is, absent the widespread installation of an infrastructure of bio-sensing computer accessories.
[0005]
WO 03/071770
PCT/US03/04387 [0006] [0007] [0008] [0009]
This leaves two authentication factors available, namely, authenticating a person based on something the person has, such as a credit card or key fob, or based on something the person knows, such as a password or personal identification number (PIN). For some particularly sensitive applications such as ATM money withdrawals, both factors might be desirable.
Currently, a user of an ATM engages an authentication device such as a credit card with the ATM, and then inputs a PIN. In this way, two factor authentication is achieved. However, the ATM must transmit both the secret information on the card and the PIN to a central bank computer for authentication. Consequently, the link between the bank and the ATM must be secure to prevent a thief from eavesdropping on the line and discovering both authentication factors, which otherwise could enable the thief to steal money from the user's account. This places a considerable burden on the link infrastructure.
The above-identified patent applications disclose hand-held sonic-based tokens that a person can manipulate to transmit an acoustic signal representing secret information to a device, referred to as an authenticator, verifier, or receiver, to authenticate the person based on the signal. As recognized in those applications, the advantage of sonic-based tokens is that a large installed infrastructure already exists to receive and transmit sound and electronic signals derived from sound. Specifically, the global telephone system exists to transmit data representative of acoustic information, and apart from telephones many computing devices that are now linked by this same system (as embodied in the Internet) have microphones and speakers (or can easily be modified to have them).
As recognized herein, when used in the context of ATMs, sonic tokens have the advantage of transmitting the private information on the token to the ATM in a fashion that prevents the ATM from being able to forge the private information without a confidential key. The ATM simply sends the private information to the central bank computer for authentication. Thus, neither the ATM nor the link between the ATM and the bank need be secure to protect this authentication factor. However, the present invention further recognizes that the second authentication factor - the PIN - still requires link security. This is because PINs generally consist of only 4-6 digits, and an attacker could snoop the line between the ATM and bank, and if the communication allowed a guessed PIN to be verified, the attacker
2003219752 01 May 2008 could simply try out the million or so possible PIN values and remember the one that worked until such time as the attacker could steal the token and gain access to the account. Consequently, secure communication between the bank and ATM, unfortunately, would still be 5 required.
[0010] Having recognized the above problem, the invention disclosed herein is provided.
[00010]
SUMMARY OF THE INVENTION
In a first aspect the present invention accordingly provides a method for authentication, 0 including providing at least a PIN and a confidential public key to an authorizing computer; establishing a communication link between the authorizing computer and at least one receiver remote from the computer, the communication link not being constrained to be secure; receiving, at the receiver, at least one acoustic signal representative of at least one private key-generated signal, the receiver transforming the acoustic signal to a signature signal; receiving, at the receiver, the PIN, the 5 PIN being received separately from the acoustic signal; encrypting the signature signal with the PIN to render an encrypted signature signal; and sending the encrypted signature signal to the authorizing computer for verification of the signature using the PIN and confidential public key.
In a second aspect the present invention accordingly provides a system for two-factor authentication over a link not constrained to be secure, including at least one portable token generating 0 at least one wireless signal representing a digitally signed message; at least one receiver receiving the wireless signal and a PIN, the PIN being received separately from the wireless signal, the receiver encrypting the signed message with the PIN to render an encrypted signed message; and at least one authorizing computer receiving at least the encrypted signed message over the link, the authorizing computer accessing the PIN and a confidential public key to attempt to verify the signed message.
In a third aspect the present invention accordingly provides a system for authentication including an authorizing computer accessing at least a PIN and a confidential public key and communicating over a link with at least one receiver remote from the computer, the communication link not being constrained to be secure, the system including means for receiving, at the receiver, at least one wireless signal representative of at least one digital signature produced from a private key, 30 the receiver transforming the wireless signal to a signature signal; means for receiving, at the receiver, the PIN; and means for encrypting the signature signal with the PIN to render an encrypted signature signal, wherein the encrypted signature signal is sent to the authorizing computer over the link for verification of the signature using the PIN and confidential public key.
In a fourth aspect the present invention accordingly provides a computer readable medium containing instructions for controlling a computer system to perform a method, the method including providing at least a PIN and a confidential public key to an authorizing computer; establishing a communication link between the authorizing computer and at least one receiver remote from the computer, the communication link not being constrained to be secure; receiving, at the receiver, at
2003219752 01 May 2008 least one acoustic signal representative of at least one private key-generated signal, the receiver transforming the acoustic signal to a signature signal; receiving, at the receiver, the PIN, the PIN being received separately from the acoustic signal; encrypting the signature signal with the PIN to render an encrypted signature signal; and sending the encrypted signature signal to the authorizing computer for verification of the signature using the PIN and confidential public key.
The details of the present invention, both as to its structure and operation, can best be understood in reference to the accompanying drawings, in which like reference numerals refer to like parts, and in which:
BRIEF DESCRIPTION OF THE DRAWINGS [0018] Figure 1 is a block diagram of the present system for audio-based authentication; and [0019] Figure 2 is a flow chart of the present logic.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT [0020] Refening initially to Figure 1, a system is shown, generally designated 10, that includes a portable hand-held token 12 that can be configured as a key fob or other small device. The present invention, however, applies to other token configurations, such as mobile communication stations including laptop computers, wireless handsets or telephones, data transceivers, or paging and position determination receivers that can be hand-held or portable as in vehicle-mounted (including cars, trucks, boats, planes, trains), as desired. Wireless
WO 03/071770
PCT/US03/04387 communication devices are also sometimes referred to as user terminals, mobile stations, mobile units, subscriber units, mobile radios or radiotelephones, wireless units, or simply as users and mobiles in some communication systems.
[0021] In any case, the token 12 can generate an acoustic signal, represented schematically by the lines 14, that can be received by a receiver 16. The receiver 16 is associated with authorizing computer 18. In an illustrative embodiment, the receiver 16 is an automatic teller machine (ATM) and the authorizing computer 18 is a bank main computer, although it is to be understood that the receiver 16 may be a receiving device associated with, e.g, a building, a home, a vehicle, or any other component to which it is desired to limit access to preauthorized users using two factor authentication. It is to be further understood that while the preferred token 12 is a sonic token that generates an acoustic signal, the present principles apply to other wireless signal-generating tokens including those that might use electromagnetic wave wireless communication principles, e.g, radiofrequency (rf) such as Bluetooth and infrared, to transmit the below-disclosed digital signature to the receiver 16.
[00012] [0022] The preferred acoustic signal 14 can represent a digital signature that is generated using a private key stored in an electronic data store 20 of the token 12. A pseudorandom number (PN) generator 21 can also be included on the token 12. Corresponding confidential public keys or confidential public key identifications can also be stored therein for purposes to be shortly disclosed.
[0023] In accordance with private key/public key principles known in the art and set forth in,
e.g, the National Institute for Standards and Technology (NIST) Federal Information Processing Standards Publication 186-2, January, 2000, the signature algorithm in the token 12 (executed by a microprocessor 22 within the token 12) receives as input (and thus combines) the private key and at least a portion of the message to be signed and with a random number k from the PN generator 21 to render a digital signature which is a random pair (r,s). Preferably, the microprocessor 22 executes the signature algorithm upon receipt of activation signals from, e.g, one or more activation elements 24 such as toggle switches, voice activation devices, or pushbuttons. The message being signed and the identity of the confidential public key corresponding to the private key also are preferably included in the signal generated by the microprocessor 22. It is to be understood that the microprocessor 22
WO 03/071770
PCT/US03/04387 can include a digital processor proper as well as necessary clocks, analog to digital conversion circuitry, and digital to analog conversion circuitry known in the art.
[0024] The microprocessor 22 accesses the data store 20, such that when multiple activation elements 24 are used, one or more can be associated with a respective private key in the store 22. The electronic signature signals are sent to an audio speaker 26 for transformation of the electronic signature signal to the acoustic signal 14. The acoustic signal may or may not be audible. If desired, a microphone 28 can also be provided on the token 12 to receive acoustic signals and transform them to electronic signals, which are sent to the microprocessor 22 for processing. When EM wave wireless principles are used, the speaker 26 is replaced by, e.g., an rf transmitter or IR transmitter.
[00013] [0025] The preferred acoustic signal 14 is received by a microphone or other acoustic receiving device 30 at the receiver 16. The acoustic signal is transformed by the microphone 20 back to an electronic signature signal (with accompanying confidential public key ID and original pre-signed message, if desired) and sent to a microprocessor 32, which may access a data store 34 if desirable. If desired, a speaker 36 can also be provided on the receiver 16 to send acoustic signals back to the token 12, which signals are received by the microphone 28 on the token 12.
[0026] When the receiver 16 is an ATM and the authorizing computer 18 is a central bank computer, the authorizing computer 18 can include a processor 38 that accesses a data store 40 to selectively grant authorization by verifying (or not) the digital signature received from the receiver 16. The data store 40 can include a data structure such as a list or database table which stores the confidential public key (and its ID) that is associated with the private key represented by the signal. In any case, the link 41 connecting the bank with the ATM need not be secure, owing to the novel use of cryptography disclosed below.
[0027] Figure 2 shows the logic of the present invention. Commencing at block 42, the confidential public key(s) associated with the token 12, along with the IDs of the public keys, are provided to the authorizing computer 18 (e.g., main bank computer). Also, the user's PIN is provided. This provision is done securely, either in person or over a secure connection. By confidential public key is meant a public key in accordance with private key/public key
WO 03/071770
PCT/US03/04387 principles known in the art, except that the confidential public key is not publicly accessible, but rather is provided only to trusted entities, such as a main bank computer.
[00014] [0028] Moving to block 44, when a user manipulates one of the activation elements 24 the signature algorithm in the token 12 receives as input the private key, a pseudorandom number, and a message, such as all or a portion of a timestamp, to generate an electronic signature, e.g, a random pair (r,s). The user then inputs both factors of authentication into the receiver 16. Specifically, at block 46 the digital signature is wirelessly (e.g, acoustically) sent to the receiver 16, along with the message that was signed and if desired the ID of the corresponding confidential public key, and at block 48 the user inputs the PIN using, e.g, the numeric keypad that is provided on most ATMs. The desired transaction (e.g, withdrawal, funds transfer, etc.) is entered at block 50. It is to be understood that the steps at blocks 46, 48, and 50 can be executed in any order.
[0029] In accordance with the present invention, at block 52 the receiver 16 encrypts the signature (r,s) with the PIN. This encryption can be a symmetric encryption using, e.g, AES encryption principles. The encrypted signature, along with the unencrypted confidential public key ID and unencrypted pre-signed message being signed (e.g, a timestamp or least two significant bits thereof) are sent to the main computer processor 38.
[0030] At block 54, the main processor 38 first decrypts the digital signature using the PIN.
Then, using the confidential public key ED and original pre-signed message, the processor retrieves from the data store 40 the appropriate confidential public key and verifies the signature in accordance with public key/private key principles known in the art. If verification is successful, the authorizing computer 18 signals the receiver 16 to allow access. In the case of an ATM verifier 16 and bank computer authorizing computer 18, the bank computer signals the ATM to execute the requested transaction.
[00015] [0031] It may now be appreciated that an attacker who might intercept ATM-bank communications on the link 41 could not deduce the PIN. Specifically, decrypting the signature using the correct PIN will yield the equivalent of decrypting it using an incorrect PIN, i.e, a random pair that can't be understood without verifying the signature, something that cannot be done without the confidential public key and the data being signed (note that
2003219752 01 May 2008 only the least significant bits of the timestamp are transmitted). This feature removes the final requirement for security on the link 41.
[0032] While the particular SYSTEM AND METHOD FOR ACOUSTIC TWO FACTOR AUTHENTICATION as herein shown and described in detail is fully capable of attaining the above5 described objects of the invention, it is to be understood that it is the presently preferred embodiment of the present invention and is thus representative of the subject matter which is broadly contemplated by the present invention, that the scope of the present invention fully encompasses other embodiments which may become obvious to those skilled in the art, and that the scope of the present invention is accordingly to be limited by nothing other than the appended claims, in which reference to an element 0 in the singular is not intended to mean one and only one unless explicitly so stated, but rather one or more. All structural and functional equivalents to the elements of the above-described preferred embodiment that are known or later come to be known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be encompassed by the present claims.
Moreover, it is not necessary for a device or method to address each and every problem sought 5 to be solved by the present invention, for it to be encompassed by the present claims.
Furthermore, no element, component, or method step in the present disclosure is intended to be dedicated to the public regardless of whether the element, component, or method step is explicitly recited in the claims. No claim element herein is to be construed under the provisions of 35 U. S. C. § 112, sixth paragraph, unless the element is expressly recited using the phrase means for or, in the 0 case of a method claim, the element is recited as a step instead of an act.
Throughout the specification and the claims that follow, unless the context requires otherwise, the words “comprise” and “include” and variations such as “comprising” and “including” will be understood to imply the inclusion of a stated integer or group of integers, but not the exclusion of any other integer or group of integers.
The reference to any prior art in this specification is not, and should not be taken as, an acknowledgement of any form of suggestion that such prior art forms part of the common general knowledge.
It will be appreciated by those skilled in the art that the invention is not restricted in its use to the particular application described. Neither is the present invention restricted in its preferred 30 embodiment with regard to the particular elements and/or features described or depicted herein. It will be appreciated that various modifications can be made without departing from the principles of the invention. Therefore, the invention should be understood to include all such modifications in its scope.
2003219752 01 May 2008
Contents5
1 sheet
Sheet 1
67 members in 17 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10077365 | United States of America | – | |
| 7736502 | United States of America | A | |
| 10139873 | United States of America | – | |
| 13987302 | United States of America | A | |
| 0304387 | United States of America | W |
Members67
| Document | Office | Kind | |
|---|---|---|---|
| US2003120925A1 | United States of America | A1 | |
| WO03056745A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002364095A1 | Australia | A1 | |
| US2003159050A1 | United States of America | A1 | |
| CA2476485A1 | Canada | A1 | |
| WO03071770A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003219752A1 | Australia | A1 | |
| TW200307438A | Taiwan Province of China | A | |
| US2004133789A1 | United States of America | A1 | |
| KR20040075026A | Republic of Korea | A | |
| EP1464138A1 | European Patent Office (EPO) | A1 | |
| US2004221166A1 | United States of America | A1 | |
| MXPA04007869A | Mexico | A | |
| MXPA04007869A | Mexico | A | |
| EP1481535A1 | European Patent Office (EPO) | A1 | |
| AU2004301642A1 | Australia | A1 | |
| CA2533316A1 | Canada | A1 | |
| WO2005011191A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2004262288A1 | Australia | A1 | |
| CA2532812A1 | Canada | A1 | |
| WO2005013180A2 | World Intellectual Property Organization (WIPO) | A2 | |
| NZ534700A | New Zealand | A | |
| BR0307657A | Brazil | A | |
| JP2005514831A | Japan | A | |
| CN1620779A | China | A | |
| JP2005518721A | Japan | A | |
| CN1650603A | China | A | |
| IL163527A0 | Israel | A0 | |
| RU2004127588A | Russian Federation | A | |
| CO5611229A2 | Colombia | A2 | |
| MXPA06000801A | Mexico | A | |
| MXPA06000804A | Mexico | A | |
| EP1647106A1 | European Patent Office (EPO) | A1 | |
| EP1654688A2 | European Patent Office (EPO) | A2 | |
| KR20060052856A | Republic of Korea | A | |
| KR20060056334A | Republic of Korea | A | |
| EP1464138A4 | European Patent Office (EPO) | A4 | |
| EP1481535A4 | European Patent Office (EPO) | A4 | |
| CN1842989A | China | A | |
| TWI268688B | Taiwan Province of China | B | |
| JP2006528391A | Japan | A | |
| JP2007507916A | Japan | A | |
| WO2005013180A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US7251730B2 | United States of America | B2 | |
| CN101061663A | China | A | |
| RU2313916C2 | Russian Federation | C2 | |
| AU2003219752B2This record | Australia | B2 | |
| US7487362B2 | United States of America | B2 | |
| US7533735B2 | United States of America | B2 | |
| US2009141890A1 | United States of America | A1 | |
| EP1481535B1 | European Patent Office (EPO) | B1 | |
| KR100952551B1 | Republic of Korea | B1 | |
| AT462239T | Austria | T | |
| ATE462239T1 | Austria | T1 | |
| IL163527A | Israel | A | |
| DE60331817D1 | Germany | D1 | |
| JP4565840B2 | Japan | B2 | |
| CN101944246A | China | A | |
| JP2011008801A | Japan | A | |
| JP4648313B2 | Japan | B2 | |
| JP4680505B2 | Japan | B2 | |
| US7966497B2 | United States of America | B2 | |
| KR101059405B1 | Republic of Korea | B1 | |
| EP1654688A4 | European Patent Office (EPO) | A4 | |
| CN101061663B | China | B | |
| US8391480B2 | United States of America | B2 | |
| CN103793817A | China | A |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent ceased section 143(a) (annual fees not paid) or expiredExpiredMK14 | MK14 | |
| Letters patent sealed or granted (standard patent)GrantedFGA | FGA |
Numbers
- Publication
- 2003219752
- Application
- 219752
Titles
- English
- System and method for acoustic two factor authentication
Classification
- CPC, 21
- G07F7/1008
- G06Q20/3272
- G06Q20/341
- G06Q20/346
- G06Q20/367
- G06Q20/3672
- G06Q20/3674
- G06Q20/3821
- G06Q20/3829
- G06Q20/4014
- G06Q20/40975
- G07F7/1016
- G07F7/1025
- G07F19/20
- H04L9/3226
- H04L9/3234
- H04L2209/80
- H04L63/0853
- H04L2463/082
- H04W12/65
- H04W12/069
- IPC, 5
- G06F21 31
- G06F21 34
- G07F7 10
- G09C1 00
- H04L9 32